Answer in brief
CVE-2026-102371 records a Medium severity (CVSS 5.7) vulnerability in wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments. The current sources do not mark it as known exploited. The current feed maps Canonical/Ubuntu Pro for WSL (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Canonical/Ubuntu Pro for WSL (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Canonical/Ubuntu Pro for WSLgeneric | >=0.1.1 <0.1.19ubuntu2 || >=0.1.1 <0.1.18~24.04.3 || >=0.1.1 <0.1.18~22.04.2 || >=0.1.1 <0.1.18~20.04.2 | 0.1.19ubuntu2, 0.1.18~24.04.3, 0.1.18~22.04.2, 0.1.18~20.04.2 |
Published upstream
Sep 29, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 29, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 29, 2026
In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding mitigations (such as hidepid), which is the default in WSL, an unprivileged local user or process in the same WSL instance can read the token from /proc/<pid>/cmdline while the attach process is running. The leaked token could then be used to attach other machines to the victim's Ubuntu Pro subscription and gain unauthorized access to Ubuntu Pro services.
Quoted source text, attributed separately from HOL analysis.